Welcome Guest. | Log In | Register | Membership Benefits

The SpiderLabs Report


Posted by Robert Richardson @ 08:14 AM ET | Jan 29, 2011

A look at the Trustwave Cyber Crime report

Continue reading "The SpiderLabs Report"


Topics:   CS Island



Anonymity And Nonversations


Posted by Robert Richardson @ 06:14 AM ET | Jan 09, 2011

There are lots of lessons for the security industry in the Wikileaks case, including learning how to talk past each other.

Continue reading "Anonymity And Nonversations"


Topics:   CS Island



There's A Recipe For That


Posted by Robert Richardson @ 11:09 AM ET | Jun 15, 2010

Back in the dark ages when I was a programmer, I became horribly fascinated with a tool called make. It was a tool for dealing with the complexities of, well, making finished executable code.

Continue reading "There's A Recipe For That"


Topics:   CS Island



Facebook: Screw You, Privacy Hugger


Posted by Robert Richardson @ 12:27 PM ET | Jun 01, 2010

As you know, Facebook recently overhauled its privacy controls -- or, well, overhauled the user interface to them. Upshot: Get over the privacy thing. But is that really what we want?

Continue reading "Facebook: Screw You, Privacy Hugger"


Topics:   CS Island



Lessons From The Volcano


Posted by Robert Richardson @ 02:44 PM ET | May 17, 2010

I had a chance to fly rather close to Iceland's Eyjafjallajokull volcano last week. On a flight back from Frankfurt, the pilot somehow got permission to divert from the scheduled flight path as we crossed Iceland to give us a closer look of the volcano.

Continue reading "Lessons From The Volcano"


Topics:   CS Island



The Idiot Threat


Posted by Robert Richardson @ 05:55 PM ET | May 06, 2010

It's been interesting to see how the failed bombing in New York's Times Square has been sifted for "lessons."

Continue reading "The Idiot Threat"


Topics:   CS Island



Will Cyber Shockwave Make Some Waves?


Posted by Robert Richardson @ 10:11 PM ET | Feb 17, 2010

With March Madness coming up, I recently spent the morning in some rather distinguished company simulating the effect of a March Madness smartphone app that turned out (within the confines of the simulation) to be malware.

Continue reading "Will Cyber Shockwave Make Some Waves?"


Topics:   CS Island



New Flaws Pry Lid Off Cloud Frameworks


Posted by Robert Richardson @ 12:21 PM ET | Feb 05, 2010

A new set of vulnerabilities came to light this week at Black Hat DC, and its appearance provides a good look at our bleak "next-gen" security future.

Continue reading "New Flaws Pry Lid Off Cloud Frameworks"


Topics:   CS Island



In Support of Poor Ol' Windows Vista


Posted by Sara Peters @ 04:49 PM ET | Oct 13, 2009

We just released the October issue of the CSI Alert to CSI members, and this month we focus on Windows 7. This issue is, in some ways, a follow-up to last year's issue, "The Fate of the Secure OS," in which I said some nice things about Windows Vista, and advised it would be imprudent to completely ignore Windows Vista -- eyes-closed, fingers-in-ears, chanting I'm-not-listening-I'm-not-listening.

Continue reading "In Support of Poor Ol' Windows Vista"


Topics:   CS Island



How Much Would You Pay To Never Have To Store PII?


Posted by Sara Peters @ 11:09 AM ET | Sep 02, 2009

Imagine a world in which you can do all manner of smooth, rich, user-friendly online commerce with mighty security. You can have complete faith in the validity of customers' login credentials and payment data (thereby reducing fraud costs, for starters). You can protect users' privacy...and never need to worry about securely storing -- or even seeing -- customers' credit card data or other legally protected personally identifiable information. Wait 12 to 18 months, and you might just have that.

Continue reading "How Much Would You Pay To Never Have To Store PII?"


Topics:   CS Island



Who Are These Followers And Followees of the Twitter Botnet?


Posted by Sara Peters @ 11:01 AM ET | Aug 17, 2009

Social networks really do bring people together, don't they? Old friends. Long-lost relatives. Bots and bot-herders. Warms the heart.

Continue reading "Who Are These Followers And Followees of the Twitter Botnet?"


Topics:   CS Island



Black Hat, Day One: Rationalizing And Reinforcing My Pessimistic World View


Posted by Sara Peters @ 12:26 PM ET | Jul 30, 2009

When I arrived in Las Vegas, I already smoldered and grumbled about the facts that online trust mechanisms are untrustworthy, and that browsers' fundamental weaknesses persist despite the fact that better browsers would make an incalculable impact on overall Web security. Yesterday's sessions simply added more kindling to the fire.

Continue reading "Black Hat, Day One: Rationalizing And Reinforcing My Pessimistic World View"


Topics:   CS Island



UPDATE: BlackHat, Kinda: 'Real' Black Hats Hack Security Experts


Posted by Sara Peters @ 12:23 PM ET | Jul 29, 2009

The rumor here is that the attacks did indeed happen, but the significance of it is actually quite small--not worth paying attention to, since attention is clearly what the attackers are seeking. More info to come... BlackHat, Kinda: Yesterday a hacking group released details (http://r00tsecurity.org/files/zf05.txt) of a number of successful attacks they conducted, apparently with the principal purpose of embarrassing some of the security industry's most well-known experts. The group claims that they collected about 75,000 passwords, including those of a few security experts speaking at the BlackHat Briefings today and tomorrow. "Welcome one and all to the real Black Hat Briefings," reads the site. "Live from the underground, coming right at you free of charge."

Continue reading "UPDATE: BlackHat, Kinda: 'Real' Black Hats Hack Security Experts"


Topics:   CS Island



Kantara Initiative: Another Effort To Get Identity 2.0 Out Of The Gate


Posted by Sara Peters @ 05:09 PM ET | Jul 06, 2009

We've been saying for a while now that better identity management -- more so than secure Web app coding or even more secure browsers -- could fuel a quantum leap in Web security. The "Identity 2.0" community can be credited with wonderful research and truly significant advancements in identity management technology. In many ways, we're poised for an identity revolution. However, the efforts have been hampered by a lack of public awareness, a lack of interoperable standards, usability concerns, and a fundamental chicken/egg problem.

Continue reading "Kantara Initiative: Another Effort To Get Identity 2.0 Out Of The Gate"


Topics:   CS Island



EU Group: Social Networks, Thirty-Party App Developers Subject To EU Privacy Laws


Posted by Sara Peters @ 01:57 PM ET | Jun 25, 2009

I just took a close look at the Article 29 Data Protection Working Party's opinion report on online social networking. While some of its recommendations are what you'd expect, others came as a surprise.

Continue reading "EU Group: Social Networks, Thirty-Party App Developers Subject To EU Privacy Laws"


Topics:   CS Island



Ruminating on CSI SX


Posted by Sara Peters @ 05:11 PM ET | May 20, 2009

Citizens of the Information Security Nation, to you I say Classify and inventory your data and assets! Tedium? Odium? Delirium? Yes, probably all three. But worth the trouble.

Continue reading "Ruminating on CSI SX"


Topics:   CS Island



Tippett To Discuss Verizon Breach Report


Posted by Sara Peters @ 12:47 PM ET | May 14, 2009

Dr. Peter Tippett, vice president of research and intelligence for Verizon Business Security Solutions, will discuss the results of the company's "2009 Verizon Business Data Breach Investigations Report" (DBIR) at CSI SX: Security Exchange, taking place May 17-21 in Las Vegas.

Continue reading "Tippett To Discuss Verizon Breach Report"


Topics:   CS Island



SIEM Case Study: Israeli E-Government ISP


Posted by Sara Peters @ 04:04 PM ET | May 12, 2009

Want a case study on the slings and arrows of outrageous SIEM implementation? Sure you do. (Really. You do. Trust me on this one.)

Continue reading "SIEM Case Study: Israeli E-Government ISP"


Topics:   CS Island



A Cloud Might Save You Money...But What If The Cloud Goes Broke?


Posted by Sara Peters @ 12:29 PM ET | Mar 25, 2009

I've been talking quite a bit about whether or not (not) users of cloud services can prove compliance with security, privacy, and e-discovery laws. Now a story from The Register has me thinking about yet another issue -- the inescapable question of a service provider's financial stability.

Continue reading "A Cloud Might Save You Money...But What If The Cloud Goes Broke?"


Topics:   CS Island : Security Services Tech Center



BBC Responds To Legality Issues Of Recent Tech Show


Posted by Sara Peters @ 01:20 PM ET | Mar 19, 2009

Yesterday Nick Reynolds of the BBC directed me, as well as many other writers, to the BBC's official response to allegations that its technology show, Click, violated the U.K.'s Computer Misuse Act when it purchased and used a botnet as part of an investigative report into cybercrime.

Continue reading "BBC Responds To Legality Issues Of Recent Tech Show"


Topics:   CS Island



BBC Botnet Experiment IS Illegal, No Matter What They Say


Posted by Sara Peters @ 03:05 PM ET | Mar 17, 2009

Saturday, "Click"--"the BBC's flagship technology programme"--broadcast an investigative report on cybercrime. The exciting thing about this particular program is that they purchased and used a botnet as part of their investigation. The creators of the program are under the impression that their experiment was perfectly legal, because they had no criminal intent. They are mistaken.

Continue reading "BBC Botnet Experiment IS Illegal, No Matter What They Say"


Topics:   CS Island



See How I Suffer For My Science?


Posted by Sara Peters @ 11:21 AM ET | Mar 12, 2009

Today I saw two fraudulent charges on my bank account, and a few weeks ago I accidentally wiped off all of the data from my BlackBerry. Why? Because I love too much.

Continue reading "See How I Suffer For My Science?"


Topics:   CS Island



Peter Parker's Uncle Ben Would Not Approve


Posted by Sara Peters @ 02:03 PM ET | Mar 03, 2009

Note to Web browsers: With great power comes great responsibility.

Continue reading "Peter Parker's Uncle Ben Would Not Approve"


Topics:   CS Island



Could Slimmer OSes Lead To Better Mobile Device Security?


Posted by Sara Peters @ 06:15 PM ET | Feb 10, 2009

Maybe I'm stretching a bit, but let's say that operating system developers slimmed down their standard OSes enough so that eventually they'd be skinny enough to have a career in fashion and, more important, run on mobile devices. And, if so, would this be a good thing for mobile device security?

Continue reading "Could Slimmer OSes Lead To Better Mobile Device Security?"


Topics:   CS Island



Can You Vote for Me Now? Estonia First Country to Cast Cell Phone Votes


Posted by Kristen Romonovich @ 03:51 PM ET | Dec 16, 2008

The Estonian Parliament has passed a law that will allow citizens to vote via cell phone by 2011. In the past, Estonians were able to cast their votes over the Internet, which apparently worked seamlessly despite security concerns. (See Sara Peters' coverage of e-voting in Estonia in the November 2005 Alert, Academic Group Publishes Criticisms of e-Voting; membership required.)

Continue reading "Can You Vote for Me Now? Estonia First Country to Cast Cell Phone Votes"


Topics:   CS Island




Go on to the weblog archives...






  1. Cookies, Social Media And FireSheep
  2. SMB Guide To Credit Card Regulations, Part 2: The Low-Hanging Fruit
  3. HP And The Scary Corporate Fifth Column Concept
  4. Taking USB Attacks To The Next Level
  5. NoSQL: Not Much, Anyway
  1. Taking Cybersecurity Lessons To The Bank
  2. Researchers See Real-Time Phishing Jump
  3. 'BlackSheep' Sniffs Out Firesheep WiFi-Hacking
  4. Slideshow: Ten Free Security Monitoring Tools
  5. A Different Spin On Sleuthing Stuxnet
  6. M&A Activity Muddles Database Security
  1. Secure Managed Web Hosting Saves 960.gs from Malicious Hackers
  2. Access Governance as a Business Service: An Integrated Strategy for Automation with ITSM
  3. Business Driven Access Management and Governance: Simplifying the Delivery and Governance of Access Throughout
 
 


 
  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag
 
  May 2012
April 2012
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
  June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
 
Featured Webcasts
Featured Whitepapers
Featured Reports